PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-37164 Hewlett Packard Enterprise (HPE) CVE debrief

CVE-2025-37164 is a Hewlett Packard Enterprise OneView code injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2026-01-07. Because it is on the KEV list, organizations should treat it as a priority remediation item and apply HPE’s mitigations as soon as possible; if mitigations are not available, CISA’s guidance is to discontinue use of the product. No CVSS score was supplied in the source corpus.

Vendor
Hewlett Packard Enterprise (HPE)
Product
OneView
CVSS
CRITICAL 10
CISA KEV
Listed
Original CVE published
2026-01-07
Original CVE updated
2026-01-07
Advisory published
2026-01-07
Advisory updated
2026-01-07

Who should care

HPE OneView administrators, infrastructure and virtualization teams, security operations, vulnerability management, and any organization that depends on OneView for management of HPE environments.

Technical summary

The supplied corpus identifies the issue as a code injection vulnerability in HPE OneView and confirms it was added to CISA’s KEV catalog on 2026-01-07. The corpus does not provide affected versions, attack prerequisites, or a CVSS score, so the safest interpretation is limited to the vendor product, vulnerability class, and known-exploited status. CISA’s listed response is to apply vendor mitigations, follow BOD 22-01 guidance for cloud services where applicable, or discontinue use if mitigations are unavailable.

Defensive priority

High

Recommended defensive actions

  • Review the HPE support bulletin referenced in the CISA KEV entry and apply all vendor-provided mitigations or updates immediately.
  • Inventory all HPE OneView deployments, including any cloud-hosted or externally accessible instances.
  • Prioritize this CVE ahead of non-KEV issues because CISA has listed it as known exploited.
  • If a secure mitigation path is not available, plan to discontinue use of the affected product in line with CISA guidance.
  • Validate compensating controls and monitor for any unusual activity around OneView management interfaces and administrative workflows.

Evidence notes

The evidence in the supplied corpus comes from CISA’s Known Exploited Vulnerabilities source item and its metadata, which identify the product as HPE OneView, the vulnerability as a code injection issue, and the date added as 2026-01-07 with a due date of 2026-01-28. Official reference links were also provided for the CVE record, NVD entry, and CISA KEV catalog. The corpus does not include version ranges, exploit details, or a CVSS score.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-37164 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-37164

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-37164 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-37164

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.